IT.COM

advice How Safe Are Your Domain Names?

Spaceship Spaceship
Whether you are the king of domains and sitting on countless super valuable domains or someone just starting out who spent days scraping through dropping lists to buy a handful of domains you found that others may have overlooked, our portfolios are special to us. They are a part of who we are and the result of the hard work we have put into them. In many cases they represent years of hard work. Our domains are important and valuable in many ways and they deserve to be protected and safe. We work too hard to build up a domain portfolio to have it taken from us in one day. Even if you are not sitting on a one-letter .com domain, the pain is just as real if you lose your domain you use for your main email address or small business or some of the drops you were able to beat out the competition for.

We all want to think our domains are safe but I know it is in the back of everyone’s mind we wonder, have we done all we can to protect them? I want to share with you some of the best practices I have observed over the years in the hopes that it helps you to protect your domains in the future. I also really encourage you to share in the comments section anything I may have missed that you think would help others.

First let’s deal with some of the common mistakes I have seen that people don’t realize can hurt them until it is too late. You should only let people you have complete trust in have access to your domains. I am surprised by how many people let friends, employees, webmasters, etc register or manage their valuable domains or have access to their account login information. Do you let your Webmaster login to manage your website or DNS? I have seen too many issues where a person doesn’t have complete control over their domains and the other party takes the name or disappears for whatever reason taking the account access with them. Many times this is not malicious but the other party moves or leaves the industry and their old email doesn’t work and now you have no way to contact them to get the account data back.

It is also very important to note that the registrant contact on the Whois is very important. When putting the registrant contact information on your domain, a name like Domain Admin may seem great at the time but when push comes to shove and you want to prove ownership of the domain, try proving in court that your name is domain admin. This can be done if you put in a company name as well but, if you use a company name on the Whois use a real company name not something made up. Again when you need to prove ownership because you can’t access your account, or someone took your domain, it is much harder to get your domains back, (if at all) if you cannot prove you are/were the registrant by valid Whois records. Bottom line, always put Whois information that is tied to you and that you can prove if needed.

Now that you know the importance of having an account and domain Whois under your control, let’s consider the account itself. Many registrars offer 2 factor authentication for logging into the account. If your registrar does not, contact them and ask for it; if it does, I highly suggest enabling it immediately. This is extremely important as a security measure in today’s landscape. I also suggest you use an email address on your registrar account that is different than your public Whois email. It makes it that much harder to have someone trick you if you are using two different emails. If you know that your registrar should only be emailing you at the email that is not on the Whois, then you can be more suspicious of emails sent to the Whois address claiming to be about your account itself. Thieves typically mine the Whois database to try and send phishing emails. Knowing you wouldn’t get an email from your registrar at the Whois email address is a nice additional layer of security. There is also the ability to add privacy to your domain’s Whois. This has pros and cons that I will not weigh here, but it is an option.

I also strongly recommend using an email address from a provider that allows 2 factor authentication as your main email on your registrar account(s). This makes it even harder for someone to access your email to perform account resets that will allow them access to your registrar account(s). This is also a good tip for any email associated with things like your banking info.

Let’s say you get a suspicious email. How do you know it is not legitimate? There are some good rules to follow. First go to the website sending you the email directly vs. clicking any links contained in the email to be safe. If you are unsure of what to do once you login or have any questions about the email that was sent to you, then forward it as an attachment to the company that the email claims to be from and ask them if they sent it. Also feel free to call their support. Do whatever it takes to be safe by taking some extra steps.

Something else you can do is look at the full email header. This is normally hidden in most mail applications, but there is usually a way to view it ("Show original" option in Gmail). It will tell you the real sender and their IP address. Doing a quick search online will show you plenty of articles on how to identify a phishing email. When you discover an email you were sent was a phishing attempt, please help the company out by forwarding it to their abuse department so they can work on taking it down to prevent it from impacting others who are not as savvy as you.

OK so you know all this stuff and you got tricked anyway. I know it happens, we cannot always be on our guard and sometimes things will slip by. This is why the extra steps including 2 factor authentication are so important, but if someone manages to get to your domains and move them out, what should you do?

The first step is to contact your registrar, the one who you had your domains registered with. They will usually have steps in place to assist you with this. The next thing to do is to contact the authorities. A theft has occurred, so contact someone who has authority to deal with Internet crimes. In the United States, it is the FBI.

I would also think about what domains were stolen and how they were stolen, meaning if any of the domains stolen are ones you use for important emails, or if your email was compromised on your account, then you will need to think about what else is tied to those emails. If you have bank accounts tied to them, or other important accounts, the thief who now can access your emails is just a password reset away from draining those accounts.

Lastly, be vocal. Let others know about the domains and share it on forums or blogs or wherever you can. The more people who know about the domains being stolen, the better your chances are at finding some kind of resolution. The less options the thief has to sell the domain(s), the better. It is also important to protect others. For instance, if I do not know a domain I am buying is your stolen domain, I may pay a thief a lot of money for a domain, which may ultimately be returned to you as the rightful owner, and now I am out real money and the thief still has a profit. Sharing the information in as many places as possible helps protect others as well as yourself.

If all else fails and you cannot retrieve your domain through normal channels, there are many competent attorneys in the field who can provide you with good counsel. I would encourage you to contact one you can trust who is familiar with domain law. This is usually expensive and time consuming, so put as much time in updating your security upfront as you can.
 
34
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
HI @Joe Styler are we allowed to have two accounts at Godaddy. I'm thinking that I'll move my more valuable domains into an account with two factor and keep the other ones in the regular account.
 
0
•••
HI @Joe Styler are we allowed to have two accounts at Godaddy. I'm thinking that I'll move my more valuable domains into an account with two factor and keep the other ones in the regular account.
You can create two accounts with us.
 
0
•••
0
•••
We were able to get the domain names back for him. I think the best thing for everyone to do is follow the advice of the article to help prevent the thefts. There were a couple things that could have helped that the blog points out and then once the names were taken he did what it said by contacting the registrar who was able to help and going public with the thefts all of which help. 2FA is a must these days and using separate emails is also very helpful as I am seeing more and more reports of people on the forums and blogs getting phished.
 
1
•••
Never had a issue with godaddy they hold my ll.com and countless nnnn.com lll.coms and the rest of the portfolio.

domains are only as secure as you really allow them to be ..treat your domains like money in a bank.

FX
 
3
•••
@Joe Styler
I think a good idea would be to add some extra steps when domains are transferred from GD to China as it seems these are the ones hardest to get back.


(Please delete previous post as didn't get the mention correct.)
 
2
•••
we look at a lot of things to keep the names safe and still let domain investors and others move domains freely when they have a sale. There are other things to come on GoDaddy to help with security, but in the meantime 2FA is very important and something you can implement now.
 
1
•••
we look at a lot of things to keep the names safe and still let domain investors and others move domains freely when they have a sale. There are other things to come on GoDaddy to help with security, but in the meantime 2FA is very important and something you can implement now.
What I would like to see:
if someone logs in to my account from a country other that my own - put my account on lockdown and send me unlock code via text message.
Lock could be for only for 72 hour - it would prevent any theft and still let me log in if I don't have a cell phone with me.
 
3
•••
@JoeStyler I think a good idea would be to add some extra steps when domains are transferred from GD to China as it seems these are the ones hardest to get back.
Completely agree with you.

we look at a lot of things to keep the names safe and still let domain investors and others move domains freely when they have a sale. There are other things to come on GoDaddy to help with security, but in the meantime 2FA is very important and something you can implement now.

I never thought that someone can steal the domains from any account. Even there are so many strict restrictions and policies by registrars and ICANN. Still these things happen. I just enabled 2FA and verifying my domains in GD and all other registrars account. IMO GD is best in among registrars because of their quick support and easy to use interface.
 
1
•••
Two step id + secure email + phone and Uniregistry = Happiness

Godaddy = GET OUT OF HERE
 
1
•••
i think that the USB solution like mentioned by Fabulous would be great!
i'm enter and exit tons of accounts everyday.
If i keep a 2FA for each, i need 10x times more to log in. We must find another solution.
Maybe also an external device where we can put the fingerprint...
 
0
•••
i think that the USB solution like mentioned by Fabulous would be great!
i'm enter and exit tons of accounts everyday.
If i keep a 2FA for each, i need 10x times more to log in. We must find another solution.
Maybe also an external device where we can put the fingerprint...

Fort that reason, I am transferring all my domains to Uniregistry. On registrar to control them all!
 
0
•••
Fort that reason, I am transferring all my domains to Uniregistry. On registrar to control them all!
Do they offer a USB or fingerprint device? I have 2FA with them but if they are like James Bond I'd like to know :)
 
2
•••
your account.
- The Executive Lock, which is able to be applied to all or your most valuable domains, which only Fabulous staff can remove under your customisable conditions.
This seems like an excellent solution for anyone not using the DTVS (domain transfer verification service).
I've mentioned this before, but have received no response. Using a different email for the registrar account is the right way to go, however GoDaddy's system is set up to undermine that security measure. Anytime a domain is pushed into my account ( eg after purchasing an expired domain at auction ), the whois is automatically set to reveal to the world my secret registrar account email address rather than correctly displaying the default whois email address defined in the settings. It's really frustrating! This doesn't happen when a domain is transferred in from another registrar so I'm not sure why this needs to be handled this way for pushes. Is there any chance that this could be corrected?
I've never noticed this before. How long before the whois is changed to the default registrant contact info, or does it have to be done manually?

But even if your email is hacked and password reset is attempted, won't the 2FA step defeat this? The hacker cannot turn off 2FA or enter a different cell number (to receive the code) unless they gain access to the account, and they can't gain access without the 2FA code. Correct?
 
0
•••
1
•••
After enabling 2-step verification. I'm getting this error when inputting password + code


Authentication failed. You entered an incorrect username or password.

100% correct username and password entered
 
0
•••
I've never noticed this before. How long before the whois is changed to the default registrant contact info, or does it have to be done manually?

It has to be done manually.
 
0
•••
Entering code 2-3 minutes later after getting the code have solved my problem so far.
 
0
•••
2
•••
I would really like to use a separate email for GD registrar admin, rather than the publicly shown Whois one. However, I am concerned to see the posts here about GD pushes of expired name sales into ones account, using the supposedly separate email for Whois purposes. Seems to completely defeat the point. Any time line on a fix for this?

I have also looked into 2FA, but am concerned how this would affect my use of the GD Auctions. I am in and out of GD Auctions multiple times a day. Since I have to log in repeatedly (as I time out often) I think using 2FA for this would drive me insane.

Is there any way GD could enable 2FA for account changes but not necessarily logging in and out to GD Auctions?
 
2
•••
I have also looked into 2FA, but am concerned how this would affect my use of the GD Auctions. I am in and out of GD Auctions multiple times a day. Since I have to log in repeatedly (as I time out often) I think using 2FA for this would drive me insane.

Is there any way GD could enable 2FA for account changes but not necessarily logging in and out to GD Auctions?
I think the added security is well worth the extra trouble, which takes literally about 5 seconds per login. However I just signed up for Gmail's 2FA and see that they only require entering the 2FA code once per device. So no extra step for the added security after that. Just keeps someone from hacking your email from another device. That would be a welcome addition at GD.
 
1
•••
Even though the 2FA can be useful it can be problematic for many who lives in certain countries and for those who are in and out of GD many times per day.
If GD really cared for their customers and not only about money they could give people free privacy to make it harder for hackers to find the email connected to names and account.
 
1
•••
All I know is GoDaddy's DTVS was my last line of defense! The hacker had all my domain names pending transfer, had me locked out of every single account, but he couldn't do anything with them. Why? Because DTVS is amazing. On top of that, 2FA is now enabled along with multiple other redundancies.

Sure, all these accounts with 2FA, no passwords being stored in my browser or anything of the like add about an hour of extra work to my life everyday. And since i'm always in and out of every account numerous times daily, it can slow down my workflow... but you know what? Worth it. Because nothing will ever slow down my workflow like losing all my shit to some hack.
 
7
•••
All I know is GoDaddy's DTVS was my last line of defense! The hacker had all my domain names pending transfer, had me locked out of every single account, but he couldn't do anything with them. Why? Because DTVS is amazing. On top of that, 2FA is now enabled along with multiple other redundancies.

Sure, all these accounts with 2FA, no passwords being stored in my browser or anything of the like add about an hour of extra work to my life everyday. And since i'm always in and out of every account numerous times daily, it can slow down my workflow... but you know what? Worth it. Because nothing will ever slow down my workflow like losing all my sh*t to some hack.
We are interested with TAKEN part-3.When will it release?:)
 
0
•••
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back